The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


Fwd: [GENERAL] PostgreSQL 7.2.2: Security Release


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: Fri, 23 Aug 2002 23:35:59 -0400
From: Lamar Owen <[email protected]>
To: [email protected]
Subject: Fwd: [GENERAL] PostgreSQL 7.2.2: Security Release

----------  Forwarded Message  ----------

Subject: [GENERAL] PostgreSQL 7.2.2: Security Release
Date: Sat, 24 Aug 2002 00:22:17 -0300 (ADT)
From: "Marc G. Fournier" <[email protected]>
To: [email protected]
Cc: [email protected], <[email protected]>, Vince 
Vielhaber <[email protected]>

Due to recent security vulnerabilities reported on BugTraq, concerning
several buffer overruns found in PostgreSQL, the PostgreSQL Global
Development Team today released v7.2.2 of PostgreSQL that fixes these
vulnerabilities.

The following buffer overruns have been identified and addressed:

		... in handling long datetime input
		... in repeat()
		... in lpad() and rpad() with multibyte
		... in SET TIME ZONE and TZ env var

Although v7.2.2 is a purely plug-n-play upgrade from v7.2.1, requiring no
dump-n-reload of the database, it should be noted that these
vulnerabilities are only critical on "open" or "shared" systems, as they
require the ability to be able to connect to the database before they can
be exploited.

The latest release is available at:

	ftp://ftp.postgresql.org/pub/sources/v7.2.2

As well as at appropriate mirror sites.

Please report any bugs/problems with this release to:

		[email protected]

Marc G. Fournier
Co-ordinator
PostgreSQL Global Development Group


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру